:

SOFI CONFIRMS DATA BREACH AT HONG KONG UNIT

SECURITY DESK1 MIN READ
MON, JUN 8, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

SoFi has disclosed a data breach affecting its Hong Kong subsidiary after hackers accessed a third-party vendor's database containing customer information.

The financial technology company discovered that an external vendor storing customer data was compromised, exposing personal information tied to SoFi Hong Kong clients. SoFi is notifying affected customers and has launched an investigation into the breach's scope and nature. The company stated it is working with relevant authorities and the compromised vendor to contain the incident and prevent further unauthorized access. No details were immediately available regarding the number of customers impacted or specific data types accessed. SoFi said it is enhancing security measures and reviewing third-party vendor protocols to strengthen data protection. This marks a notable security incident for SoFi, which has expanded its international operations in recent years. The breach underscores ongoing risks associated with third-party data handling and vendor management in the fintech sector.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

New variants of NFCShare Android malware are being distributed as fake updates for legitimate banking applications hosted on GitHub. The scheme targets users seeking app updates through unofficial channels.

JUST NOWDev Desk

Signal has issued a statement opposing the UK's latest surveillance legislation, arguing that expanded monitoring powers do not enhance public safety. The messaging platform joins privacy advocates in raising concerns about government overreach.

2H AGOSecurity Desk

A man spent a month in jail after police arrested him for a crime despite Flock camera data placing him 5 miles away at the time of the incident. The officer apparently disregarded the timestamped evidence.

2H AGOAI Desk

Microsoft's package ecosystem was compromised for the second time in weeks, with 73 malicious packages containing a self-replicating credential stealer that activates when opened by AI agents.

2H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.